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RECEIVED 
CENTRAL FAX CENTER 
.MimnMFNTTO CLAIMS ^ ( ? ^ 

Please amend tbe following claims as indicated: 

, (currently tended) An apparatus for *«* ~* * > — """^f f |C|AL 
sy 5tOT , «-»-*^ ^ jwBc-ta ^ in with a g ,obal «mputer 

„«wo* and program «o receive selectively security audit inaction data 

b a plurality of scanning machines in communication with the global computer 
' nJLk and programmed to execute selectively . security aodt. scan of the 
^ eomputer system via the global computer network ^ !, 1^ rnachm e 

o . central computer, having a memory, configured as a database server and as a 
scheduler, in cornmunlcatlon with the secure application server and me pluflta 
^scanning marines, programmed » perform operations 

f^mprising : 

a. e^uadagevatoa a database to determine if [[al]the security aud* scan is 
currently scheduled to be run, on one of the scanning machines^"***; 

b de ^n u w l m l i uf » 1 »1 ^ troi mi n p .u ad iiii u . L n v nilnhlo t o 

^ ljim „ iij mirlft irnn ^™™r Whirl, of the plurality of 

_ umjJ i i i j: mirhi-- ; « — ***** ^ rfnrm thp smiritY audit SCan bY 
„^n p , my Wnp to identity certain ones 

nf thr ;, r that nrr conducting another security audit scan 

„ ^iri to nnrV t r"**T security unfit scan, the avadable 

„ nnninr rr hf n "" I"*™ 311 " f thP ** 

re ytatrt scan ™"F. machines; 
c copying scan-related information into a- on* of the available s canning 

machines d clumiiiL J to be civrnlnW * and instructing the scanning machine 

to begin th e security audjL scan; and 
d. recording the results of the security audit scan in thememory. 
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2, (Original) The apparatus of Claim 1 , wherein the secure application server comprises 
a Web server, 

3 (Currently Amended) The apparatus of Claim 1, wherein the central computer is 
mh , m , ,„ . Nation « u U fl to . u ji ■ I. n a ri l t hn . . thf purit y a„di. scan 

is commencing. 

4 (Currently Amended) The apparatus of Clam 1, wherein the central computer is 
further programmed to update the_database to indicate that thc security audit scan is complete. 

5. (Currently Amended) The apparatus of Claim 1. wherein the central computer is 
further programmed — < « renting notify the user of n completion of jtea-siofflty. 
audit scan. 

6. (Currently Amended) The apparatus of Claim 1, wherein when the central computer 
performs the operation in which the central computer records the results of the security audit 
scan, the central computer also copies the r^s^ta-to the database and copies a the-report to j 
the-file system on [[the]]a database machine when the security audit scan is complete. 
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eo^g «. ^^^^^^ - — » » 

- — ^^^T^ing machines to access the remote 

[[b ]]c. iristructiiig_5B§_oLtt!S *-avana . the 

^ m vi, a the-alobal computer network tound morony-penu 
computer system via_a »e-gioo »- 

..^itccanofthe remote computer system^; andj] 



9. (Canceled) 
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10. (Currently Amended) A method of auditing computer system security, comprising 
the steps of: 

fc J1 ^ jlj n L n fa » jennritv ««Bt scan of a remote computer 

■g^,, u^jn th - «™ritv audit scan of the remote computer system „ig 
tn he conducted after the schawl* mrnest is received; 
k winding the s cheduled securit y g ™ n ™ a database: 
[[a]]* accessing [[a]]the database to determine when [[a]]MiCheduled security audit 
scan of [[«] ]the remote c omputer system is to be executed; 

[[b)]d . in rn » d^ination u u on dotannininc t hat [[aftjig schgjujgd_security 

*" audit scan of the remote computer system is to be executed jn a predetermined. 
period of time, performing the following steps: 

i. copying security audit scan data into a scanning system; 

ii. causing the scanning system to establish communication with the remote 
computer system via a global computer network; and 

iii. causing the scanning system to execute [frflthe scheduled security audit 
scan of the remote computer system via the global computer network.f*»4 

iv . it orir c n rnnlt ™""™ty ""Hit ^nn of tho global oomputcr network; 

t. ti t mauUlini: n "C *" " " f ^ fcmoto °omputor nyntom that indicatoo the 
result of tho aoourity audit ooan. 

11. (New) The method of Claim 7, further comprising the step of receiving at the 
available scanning machine scan related information for the security audit scan of the remote 
computer system. 

12. (New) The method of Claim 1 1, wherein the scan related information comprises at 
least one security assessment to be conducted during the security audit scan. 

13. (New) The method of Claim 1 1, wherein the scan related information comprises an 
identity of at least one remote computer system upon which to conduct the security audit scan. 

14. (New) The method of Claim 7, further comprising the step of sending a message to a 
user interface that the security audit scan is being conducted, 
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15. (New) The method of Claim 7, wherein the security audit scan comprises a 
vulnerability assessment. 

16. (New) The method of Claim 7, wherein the security audit scan comprises a 
penetration study. 

17. (New) ThemeAodofCIaim7,f^er<»mpris 
the security audit scan in a database. 

18. (New) The method of Claim 17, wherein the result comprises at least one 
vulnerability of the remote computer system detected by the available scanning machine during 
the security audit scan. 

19. (New) The method of Claim 18, wherein the result further comprises a list of at least 
one security assessment conducted during the security audit scan. 

20. (New) The method of Claim 7, further comprising the step of determining if the 
available scanning machine is currently conducting the security audit scan on the remote 
computer system. 

21 (New) the method of Claim 7, further comprising the step of receiving from the 
available scanning machine a notification at a central computer that the security audit scan of the 
remote computer system is complete. 

22. (New) The method of Claim 21, further comprising the step of reporting at least one 
result of the security audit scan to a user interface. 

23. (New) The method of Claim 22, wherein the at least one result of the security audit 
scan is reported in response to receiving the notification at the central computer that the security 
audit scan is complete. 

24. (New) The method of Claim 10, further comprising the step of transmitting a 
message to a user interface that indicates a result of the scheduled security audit scan. 
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25 (New) The method of Claim 10, further comprising the step of storing a result of the 
scheduled security audit scan of the remote computer system in the database. 

26. (New) The method of Claim 25, wherein the result is used for a statistical analysis of 
security on the remote computer system. 

27 (New) The method of Claim 10, further comprising the step of determining which of 
a plurality of scanning systems is available to perform the scheduled security audit scan by 
elnining a schedule of each of the scanning systems to identify certain ones of * 
systems that are conducting another security audit scan or are scheduled to conduct another 
security audit scan, the available scanning systems comprising all of the scanning systems except 
for the certain scanning systems. 

28 (New) The method of Claim 10, further comprising the step of examining the 
scanning system to determine if the scheduled security audit scan is in the process of being 
conducted on the remote computer system. 

29 (New) The method of Claim 10, wherein the security audit scan data comprises at 
least one security assessment to be conducted during the scheduled security audit scan. 

30 (New) The method of Claim 10, wherein the security audit scan data comprises an 
identity of at least one remote computer system upon which to conduct the scheduled security 
audit scan. 

31. (New) Tne method of Claim 10, further comprising the step of sending a message to 
a user interface prior to the commencement of the scheduled security audit scan. 

32. (New) The method of Claim 10, further comprising the step of storing a result of the 
scheduled security audit scan of the remote computer system. 

33. (New) The method of Claim 32, wherein the result comprises at least one 
vulnerability of the remote computer system detected by the scanning system during the 
scheduled security audit scan. 

34. (New) The method of Claim 33, wherein the result further comprises a list of at least 
one security assessment conducted during the scheduled security audit scan. 



7 

PACE 1 W25 * RCVD AT 7*2/2004 1:16:22 PM [Eastern Daylight Time] * SVR:USPTO-EFXRF-1/0* DNtS:8729306 « CSID.404 572 5145 * DURATION (mm«s):0646 



02 2004 13:20 FR KING AND SPALDING 404 572 5145 TO 65278054568 1 0000 P. 11 

Application No. 09/592,404 



35. (New) The method of Claim 10, further comprising the step of determining if a 
request for an immediate security audit scan of one of a plurality of computer systems has been 
received in response to a determination that the scheduled security audit scan of the remote 
computer system will be executed outside of the predetermined period of time. 

36. (New) The method of Claim 10, further comprising the step of receiving from the 
scanning system a notification at a central computer that the scheduled security audit scan of the 
remote computer system is complete. 
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37. (New) A method of conducting a security audit scan of a remote computer system 

comprising the steps of : 

a. receiving a request to schedule the security audit scan of the remote computer 

system; 

b. recording a scheduled security audit scan in a database; 

c. accessing the database to determine when the scheduled security audit scan of (he 
remote computer system is to be executed; and 

d. in response to a determination that the scheduled security audit scan of the remote 
computer system is to be executed, performing the following steps; 

1, determining which of a plurality of scanning machines is available to 
perform the scheduled security audit scan by examining a schedule for 
each of the scanning machines to identify certain ones of the scanning 
machines that are conducting another security audit scan or are scheduled 
to conduct another security audit scan; and 

2. causing one of the available scanning machines to access the remote 
computer system and execute the scheduled security audit scan. 

38. (New) The method of Claim 37, further comprising the step of receiving at the 
available scanning machine scan related information from a central computer for the scheduled 
security audit scan of the remote computer system. 

39. (New) The method of Claim 38, wherein the scan related information comprises at 
least one security assessment to be conducted during the scheduled security audit scan. 

40. (New) The method of Claim 37, further comprising the step of sending a message to 
a user interface that the scheduled security audit scan is being conducted. 

41. (New) The method of Claim 37, wherein the scheduled security audit scan 
comprises a vulnerability assessment. 

42. (New) The method of Claim 37, farther comprising the step of recording a result of 
the scheduled security audit scan in the database. 

43. (New) The method of Claim 42, wherein the result comprises at least one 
vulnerability of the remote computer system detected by the available scanning machine during 
the scheduled security audit scan. 
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44 (New) The method of Claim 37, further comprising the step of ~»^» 
Iwne to determine if the scheduled security audit scan is m the process of 
available scanning machine to determine 
being conducted on the remote computer system. 

4, ftfcw) THe method of Claim 37, further comprising the step of receiving from the 

scan is complete. 

46 (New) Themetlrcdofaa^,*^ 
result of the scheduled security audit scan to a user interface. 

m * The method of Claim 46, wherein the at least one result is reported in 

complete. 
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